{"id":"f8b0ec91-e718-4113-a1a2-361e235f9389","engagementId":"d387bb9b-75d0-4fb5-bd72-c32d24928355","data":{"brief":{"id":"821c0b78-0512-45a0-9326-87abf2636ba4","name":"LegalZoom VDP","tagline":"LegalZoom aims to make legal help accessible to all, supporting entrepreneurs and small businesses through business formation, attorneys, and tax experts.","description":"\u003cp\u003eWe recognize the invaluable role of skilled independent security researchers in identifying security defects. Your expertise is instrumental in ensuring the continued security and integrity of our products. Thank you for your interest and we wish you success in your research.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTo maintain the highest degree of security for our products and services, we offer the opportunity for security researchers to help us identify vulnerabilities and report them to our team. The security of our infrastructure is of the utmost importance to us, so the feedback we receive is highly appreciated. It helps us to safeguard our services and deliver the best possible protection to our customers and their data.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eResearch Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAutomated web requests must be kept to under 45 requests per minute.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eDo not attempt social engineering. This includes research against employees, team members, support representatives, etc.\u2028\u003c/li\u003e\n\u003cli\u003eDo not attempt physical security testing. This includes research against offices, warehouses, data centers, etc.\u2028\u003c/li\u003e\n\u003cli\u003eDo not attempt denial-of-service (DoS) attacks. This includes application-level denial-of-service, distributed denial-of-service (DDoS), etc.\u2028\u003c/li\u003e\n\u003cli\u003eDo not attempt brute-force attacks or spam. This includes enumeration, password guessing, web directory guessing, etc.\u2028\u003c/li\u003e\n\u003cli\u003eAvoid research that sends emails, text messages, push notifications, or other communications to other users. You may test these communications on yourself, but should avoid creating more traffic than necessary.\u2028\u003c/li\u003e\n\u003cli\u003eDo not conduct security research activities on any of our vendors or other third-party partners.\u2028\u003c/li\u003e\n\u003cli\u003eIf you encounter sensitive data, stop testing immediately. This includes personally identifiable information (e.g. names, email addresses, physical addresses, phone numbers), financial data, etc. Report - potential issues and we will guide further testing.\u2028\u003c/li\u003e\n\u003cli\u003eRespect LegalZoom infrastructure, users, and other security researchers. Use your best effort to avoid causing harm to LegalZoom property or disrupting LegalZoom services.\u2028\u003c/li\u003e\n\u003cli\u003eAvoid submitting low-quality reports or those without a clear security impact.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"26d341d5-e664-44d7-8779-990072c4b638","name":"In-Scope Targets","targets":[{"id":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6","uri":"https://legalzoom.com","name":"*.legalzoom.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8dd51aab-eb6f-45a6-a74c-b2021c665d69","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"05a83ef7-98f3-453a-b162-a4dfd7bb9ef6"}],"recentChangeFlags":null},{"id":"98391d4a-bf5b-456d-855b-272f84dd59e1","uri":"https://portal.legalinc.com","name":"*portal.legalinc.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"578d804b-43b9-4f20-8fd5-1eb730ed9fbf","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"98391d4a-bf5b-456d-855b-272f84dd59e1"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"98391d4a-bf5b-456d-855b-272f84dd59e1"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"98391d4a-bf5b-456d-855b-272f84dd59e1"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"98391d4a-bf5b-456d-855b-272f84dd59e1"}],"recentChangeFlags":null},{"id":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d","uri":"https://earthclassmail.com","name":"*.earthclassmail.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7ad8ede5-5d1a-4480-8f25-d4e6702a7db8","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"b3bcdd0e-abe7-4f75-8e25-bc30011b398d"}],"recentChangeFlags":null},{"id":"e1d2387f-2005-4a3c-8ec1-f880f059714b","uri":"https://lzlegalservices.com","name":"*.lzlegalservices.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3f88c73a-4166-483a-ac67-8add4a3fc84a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis scope applies to the below systems.  Any services not expressly listed, such as any connected services, are excluded from scope and are not authorized for testing. Automated web requests must be kept to under 45 requests per minute. Additionally, vulnerabilities found in non-LegalZoom systems from our vendors fall outside of this policy\u0026#39;s scope and should be reported directly to the vendor according to their own disclosure policy, should one exist. If you aren\u0026#39;t sure whether or not a system or endpoint is in scope, contact us here or at security@legalzoom.com before starting your research.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"d387bb9b-75d0-4fb5-bd72-c32d24928355","code":"legalzoom-vdp","state":"in_progress","endsAt":null,"bountyId":"9173396f-2df7-427c-b8b3-bd6db28831db","startsAt":"2022-06-27T11:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/b08f/c66d/5f62a7e1/923e4beb905d222083c9b696bcd7b95e_image.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-06-27T11:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/legalzoom-vdp","changelogs":"/engagements/legalzoom-vdp/changelog","submissions":null,"announcements":"/engagements/legalzoom-vdp/announcements","hallOfFame":"/engagements/legalzoom-vdp/hall_of_fames","crowdstream":null},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/legalzoom-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=legalzoom-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/legalzoom-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/legalzoom-vdp/changelog","publishedAt":"2025-07-01T15:48:48.768Z","engagementChangelogUrl":"/engagements/legalzoom-vdp/changelog/f8b0ec91-e718-4113-a1a2-361e235f9389","createUserFeedbacksUrl":"/engagements/legalzoom-vdp/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}